77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Data security in the company: protection goals, standards and audit-proof structure
Platform & Strategy

Data security in the company: protection goals, standards and audit-proof structure

26 August 202614 min readBy Dr. Henrik Bauer
CIVAC

Data security includes all technical and organisational measures that ensure the confidentiality, integrity and availability of data. This guide shows protection goals, standards, obligations and the operational structure in German companies.

Data security is not a single product or a single tool, but rather the documented state in which a company verifiably maintains the three classic protection goals of confidentiality, integrity and availability (CIA) for all relevant data. In Germany, several sets of rules provide the basis in parallel: Art. 32 GDPR for personal data, ISO/IEC 27001:2022 with 93 controls for the information security management system, the BSI-Grundschutz compendium for government-related structures, the IT Security Act 2.0 and, since national implementation came into force, the NIS 2 guideline for around 29,500 companies in Germany. Anyone who is serious about data security does not keep these sources in parallel, but rather integrates them into a versioned system with a reporting line to management, checked through internal and external audits and documented with status, person responsible and receipts.

This guide is aimed at management, IT management, compliance and data protection managers in German medium-sized companies and in corporate subsidiaries. It clearly separates data protection and data security from each other, describes the three classic and three extended protection goals, assigns the most important standards (GDPR, ISO/IEC 27001:2022, NIS-2, BSI-Grundschutz), deals with TOMs, authorisation and key management, backup and emergency planning, employee training, supply chain security according to Art. 21 NIS-2 and concludes with the structure in a platform logic in which every proof can be accessed and versioned is present. Audit-proof, documented, § 32-firm.

Key Takeaways

  • Data security covers all data with the protection goals of confidentiality, integrity and availability; Data protection only treats personal data in accordance with the GDPR.
  • The documentary gold standard is an ISMS according to ISO/IEC 27001:2022 with 93 controls plus TOMs according to Art. 32 GDPR; both are managed in one system.
  • For companies affected by NIS 2, 24-hour early warning and 72-hour follow-up notification to the BSI apply; Fines range up to 10 million euros or 2% of group sales.

Data protection and data security: two disciplines, one filing cabinet

Data protection is a legal area. It protects the fundamental right to informational self-determination and applies exclusively to personal data within the meaning of the GDPR. Data security is a technical and organisational discipline. It protects all data regardless of personal reference, including construction plans, supplier prices, algorithms, source code, research results and trade secrets in accordance with the Trade Secrets Act.

Both disciplines overlap, but are not identical. A data breach according to Art. 33 GDPR is always a data security incident. A ransomware attack on production-related control systems is a data security incident, but not necessarily a GDPR reporting requirement if no personal data is affected. Anyone who separates the two disciplines arrives at the audit with two different file statuses. Anyone who integrates them has a stand. Others run compliance like a filing cabinet. We run it like software.

In practice, the responsibilities are separated: the data protection officer (DPO) is responsible for GDPR compliance, the information security officer (ISB) is responsible for the ISMS. Both work with overlapping evidence: TOMs according to Art. 32 GDPR are in fact a subset of the ISO 27001 controls; the inventory of processing activities overlaps with the asset inventory. Platform logic means: maintain the document once and access it in both views. The Information Security Officer (ISB) is the central role for the data security side, while the DPO is responsible for the data protection side. Both typically work on a shared reporting line to management. In supervisory practice, both data protection and IT security authorities are increasingly checking precisely this interface: Anyone who manages DPOs and ISBs without coordination produces contradictory evidence and loses the audit. Anyone who leads them on a common reporting line creates a status from two circles of obligations. The auditors take a closer look because ESG reporting according to CSRD has also been able to classify data protection and data security incidents as material since 2024 and thus affect the management report.

Data security protection goals: CIA and its extensions

The three classic protection goals of data security are confidentiality, integrity and availability. Confidentiality means that only authorised people have access. Integrity means that data is not changed or damaged unnoticed. Availability means that authorised people can access the data when they need it. Violations can be categorised according to protection goal: data leak violates confidentiality, manipulation violates integrity, ransomware typically violates all three.

The BSI adds three further protection goals: authenticity (proof of identity of data and senders), binding (non-repudiation, non-repudiation) and attributability. These extensions will be important in areas such as electronic contracting, qualified electronic signature according to eIDAS Regulation 910/2014, audit logging and forensic evidence preservation. Anyone who concludes contracts digitally needs authenticity and commitment as equal protection goals to CIA.

In the risk analysis, a protection requirement is determined for each asset in three or four levels: normal, high, very high. This classification controls the level of measures required. An HR database with salary information regularly has a high need for protection in all three classic goals. A publicly available marketing PDF has a need for protection of normal levels of confidentiality, but potentially high levels of integrity because manipulation would cause reputational damage. Determining protection needs is the bridge between abstract standards and concrete investments and decides how deep encryption, access control and backup strategies really need to be for each asset. It is checked at least annually and updated as necessary in the event of significant changes (new application, new process, new sub-service provider), documented with the date, person responsible and justification for the classification. In corporations, the determination of protection needs is supplemented by cluster logic: similar assets are grouped into protection requirement classes, so that control is not taken over by hundreds of individual assessments, but rather a few standardised classes.

ISO/IEC 27001:2022, BSI-Grundschutz and Art. 32 GDPR

ISO/IEC 27001:2022 is the internationally authoritative standard for an information security management system (ISMS). The 2022 version reduced the Annex A control set from 114 to 93 controls in four subject areas: organisational (37), personnel (8), physical (14) and technological (34). The transition from ISO/IEC 27001:2013 ended on October 31, 2025; Since then, only certificates according to the 2022 version are valid. Anyone who misses the transition period loses the certificate and has to re-certify.

The BSI-IT-Grundschutz is the German sister method to the Grundschutz compendium (modules, requirements, implementation instructions). It is compatible with ISO/IEC 27001 (BSI-Grundschutz certification with audit according to ISO 27001), but is much more prescriptive. BSI-Grundschutz is often required by contract or regulation for authorities, municipal companies and KRITIS operators. For most private companies, ISO/IEC 27001:2022 is the more manageable choice, with international recognition in vendor management.

Art. 32 GDPR does not itself describe which measures must be taken, but rather requires a level of protection appropriate to the risk. In practice, this means: Anyone who has implemented the relevant controls from ISO/IEC 27001:2022 or BSI-Grundschutz regularly complies with Art. 32 GDPR. CIVAC maps the 93 controls and the GDPR TOMs in a uniform matrix, so that the ISO 27001 transition is not managed in a separate project, but as regular maintenance of the Statement of Applicability. For companies with GDPR and NIS-2 obligations at the same time, the requirements from Art. 32 GDPR and Art. 21 NIS-2 can be managed as a common requirements matrix that references ISO/IEC 27001:2022 as the implementation standard. This creates an integrated document system from three parallel obligations. For group structures, this is supplemented by a group-wide security guideline in accordance with ISO/IEC 27001:2022 Appendix A 5.1, which is considered a top-level policy and must be viable in the subsidiaries without disruption. The appointment certificate, signed, filed, verifiable.

Technical-organisational measures: what actually works

Technical-organisational measures (TOMs) are not a checklist, but rather a lived security architecture. The practice can be organised into six pillars: identity and access management, network and endpoint security, cryptographic measures, backup and recovery, logging and monitoring, and organisational frameworks such as training, policies and processes. Each of these pillars must be specifically described, given a responsible role and checked in a regular effectiveness check.

Identity and access management starts with single sign-on, multi-factor authentication for all administrative access and a documented joiner-mover-leaver process. Permissions must be revoked within 24 hours of leaving; In regulated industries, this is randomly checked by auditors against the personnel list. Privileged access management with just-in-time authorizations is now standard, not a bonus, for admins of productive systems.

Cryptography includes encryption at rest and in transit, a key management process (often with HSM or Cloud KMS), a documented cryptography guideline according to BSI TR-02102 and the treatment of quantum-resistant algorithms for long-term sensitive data. Backup follows the 3-2-1 rule (3 copies, 2 media, 1 offsite) and is tested at least once a year for restorability, not just existence. Logging must be audit-proof, i.e. cannot be deleted by operational admins, and storage must comply with legal requirements (e.g. § 14 NIS2UmsuCG). CIVAC provides templates, a target/actual assessment and a maturity indicator for each of these six pillars, which is reported to management on a quarterly basis. The logic is: one TOM directory that simultaneously serves the ISO 27001 controls, the NIS 2 minimum measures and the GDPR TOMs, instead of three parallel Excel lists with competing truths. If desired, the workspace automatically generates the appendix to the AVV according to Art. 28 GDPR, the Statement of Applicability according to ISO/IEC 27001:2022 and the risk management report according to Art. 21 NIS-2 from the TOM directory.

NIS-2 and the 24/72 reporting paths for data security incidents

The NIS 2 Directive (EU) 2022/2555 obliges around 29,500 German companies from 18 sectors to adopt a new framework of measures for cybersecurity. The German implementation law NIS2UmsuCG is in the final parliamentary phase and will come into force from 2026. Essential and important facilities with 50 employees or more than 10 million euros in sales in the defined sectors are covered, plus all DNS, TLD and telecommunications providers regardless of size.

The reporting obligation is three-stage: early warning to the BSI within 24 hours of knowledge (short initial report), follow-up report within 72 hours (situation report with indicators), final report within one month (cause analysis, effectiveness of measures, lessons). Learned). The clock starts on awareness. Violations are punishable by up to 10 million euros or 2% of global group sales for important facilities, and up to 7 million euros or 1.4% for important facilities. Management is personally liable for failures in risk management.

Operationally, NIS-2 requires ten minimum measures in Article 21 NIS-2, including risk management, incident handling, business continuity, supply chain security, vulnerability management, cryptography, personnel security and multi-factor authentication. CIVAC maps these ten action fields in the workspace and maintains the 24/72 reporting path parallel to the GDPR path in accordance with Art. 33 GDPR. You can find a detailed treatment of the national implementation in our article on NIS 2 implementation in Germany. Management is personally liable for failures in risk management and cannot delegate this responsibility; The training of the management level is mandatory according to Section 38 NIS2UmsuCG, documented with a participation list and date. Deadline begins as soon as we become aware of it. Registration with the BSI must be completed within three months of entry into force, with the first report of the contact details of the responsible person. In addition, Section 30 NIS2UmsuCG requires annual proof of the effectiveness of the ten measures, documented in a report that can be requested from the BSI in samples.

Employees, training and awareness as data security factors

Over 70% of all documented security incidents in Germany (BSI management report 2024) can be traced back to human behaviour: phishing, weak passwords, mindlessly clicking on attachments, publishing sensitive data in wrong channels, passing on access data to supposed colleagues. Technical measures alone cannot solve this. Data security is half a behavioral problem, half a technical one.

Effective training follows three rules. First: short and frequent instead of once a year. 10 to 15 minutes of microlearning per month produces measurably better results than a 4-hour block once per year. Second: target group-specific. Accounting needs awareness for invoice fraud and CEO fraud, development needs secure coding, sales needs data classification in CRM. Third: measurable. Phishing simulations with click rates, awareness quizzes with scores, escalations in the event of repeated failure.

Personnel security includes further fields: confidentiality agreements before starting work, background checks for security-relevant roles (within legal limits), clear return of assets upon departure, documented sanctions in the event of violations. For regulated industries, there are additional requirements from Section 27 of the KRITIS Ordinance, BAIT, VAIT, KAIT and MaRisk. CIVAC provides a training workspace with target group-specific modules, automatic tracking of participation and receipts for the auditor. This turns awareness from compliance theater into reliable effectiveness measurement. The auditor calls, the evidence is ready. In addition, regulated industries require a documented response process to awareness findings: Anyone who clicks on a phishing simulation twice receives coaching; If you click three times, you will receive personalized training with manager information. This graduated response is described in the DSK guidance and in BSI recommendations as being more effective than pure sanction mechanics. Measure effectiveness, not just participation. Every year, the awareness metrics are aggregated in the training workspace, reported to management and linked to the ISMS action plan so that weaknesses become visible per location, per function and per language.

Suppliers, cloud and third parties: data security does not end at the factory gate

Over 60% of the applications used productively in medium-sized businesses and corporations today run outside of their own data centres: hyperscalers, SaaS, managed service providers, outsourcing partners. This shifts data security to the supplier without transferring responsibility. The shared responsibility model at AWS, Azure and Google Cloud is an industry standard, but is often misinterpreted in audits.

Practice requires three building blocks. First: a supplier audit program. Before the contract is concluded, an assessment against a fixed questionnaire (around 100 questions along ISO/IEC 27001:2022, NIS-2 Art. 21 and GDPR Art. 28). Annual re-evaluation with supporting documents during the term. Second: contractual security. Data protection order processing contract in accordance with Art. 28 GDPR, security appendix with specific requirements, audit rights, reporting obligations in the event of incidents with a deadline, standard contractual clauses 2021/914 for third country references. Third: technical integration. SSO, logging access, clear architecture diagrams, documented data flows.

NIS-2 tightens the supply chain obligation in Art. 21 Para. 2 lit. d. Essential and important facilities must actively manage the security of their supply chain and can no longer rely on the supplier being responsible. For SaaS, cloud and IT service providers, this means that they must regularly provide evidence such as pen test reports, SOC 2 reports, ISO 27001 certificates and EU data residency confirmations. With the CIVAC Supplier Auditor, this process is managed as a repeatable workflow, instead of as an annual Excel theater. This allows the document depth to be scaled per risk class. Suppliers in Class A (critical, access to productive personal data) receive annual on-site or remote audits, Class B (medium criticality) receive an annual questionnaire assessment, and Class C receive a simplified self-assessment every two years. The classification is based on the protection requirements of the affected data and the depth of access (reading, writing, administrative).

Disaster, recovery and business continuity

Data security is not evident in normal operation, but in an emergency. A resilient architecture separates three topics: incident response (response to the incident), disaster recovery (restoration of technology) and business continuity (maintenance of critical business processes). All three topics require their own plans, their own responsible people and their own exercises, but are closely interlinked in crisis situations.

Incident response follows a standardised process: identification, containment, elimination, recovery, lessons learned. NIST SP 800-61 and ISO/IEC 27035 provide the methodological basis. In practice, you need a Computer Security Incident Response Team (CSIRT) with defined accessibility, a playbook for the ten most common incident classes (ransomware, data leak, DoS, insider threat, compromised access data, phishing wave, supply chain incident, cloud misconfiguration, hardware theft, physical break-in) and a practiced escalation path to management and, if necessary, to Regulatory authority.

Disaster recovery is measured in two metrics: Recovery Time Objective (RTO, how quickly the system is available again) and Recovery Point Objective (RPO, how much data loss is acceptable). For critical applications, RTO and RPO are typically less than 4 hours and less than 1 hour, respectively; for supporting systems at 24 to 72 hours. Business continuity goes beyond this and defines how orders, payments, communication and delivery continue to run for at least 72 hours, if necessary on paper or via mobile device, even in the event of a total IT failure. The exercises (tabletop, live simulation) should be in the management calendar at least once a year, documented with minutes, findings and a list of measures. For KRITIS operators and NIS 2 essential facilities, the obligation to exercise is tightened by Section 8a BSIG or the national NIS 2 implementation, with an obligation to document effectiveness. Audit-proof, documented, § 8a-firm.

Data security with CIVAC: ISB, workspace, audit templates

Data security can be built in two ways. Classic: You hire an internal information security officer (ISB), have him acquire certificates, hire external consulting for ISO 27001, buy a GRC tool, buy an incident management tool and manage the topics in two or three systems in parallel. The setup typically takes 12 to 18 months; the running costs for medium-sized companies are between 180,000 and 420,000 euros per year.

As a compliance platform and officer-as-a-service, CIVAC is built precisely to shorten this path. If you licence the workspace for your internal representatives, then your ISB works with 490 audit templates, 93 pre-maintained controls according to ISO/IEC 27001:2022, an integrated 24/72 NIS-2 reporting path, the directory of processing activities and a documented reporting line to management. Or have our representatives order it, then CIVAC will take over the ISB role according to BSI recommendations, including an appointment certificate and SLA of 2 working days.

Both models run in the same workspace with EU data residency. The DSB and ISB strands are managed together, so that TOMs according to Art. 32 GDPR and controls according to ISO/IEC 27001:2022 exist as one source of evidence and are not maintained in two tools. This shortens security questionnaires, speeds up vendor risk assessments and makes the status verifiable at any time. Others run compliance like a filing cabinet. We run it like software. Turn reading into a mandate.: info@civac.de or the contact form on civac.de. You will usually receive an initial assessment within 2 working days, together with a proposal for a workspace licence or an ordered ISB. For regulated industries such as KRITIS or financial service providers, the initial assessment is carried out with reference to BAIT, VAIT or KAIT, so that the supervisory-relevant interfaces run from the start.

FAQ

What is the difference between data protection and data security?

Data protection is a legal area for the protection of personal data according to the GDPR and BDSG. Data security is a technical-organisational discipline that protects all data regardless of personal reference, including construction plans, source code and trade secrets. Both overlap, but are not congruent. The DSB is responsible for the first area, the ISB for the second; ideally on a shared reporting line.

Which standard will be relevant for data security in 2026?

The internationally relevant standard is ISO/IEC 27001:2022 with 93 controls in four subject areas. In Germany, the BSI-IT-Grundschutz is also relevant, especially for KRITIS operators and public bodies. For personal data, Art. 32 GDPR is added, and for institutions affected by NIS-2, Art. 21 NIS-2 with ten minimum measures from 2026 in national implementation.

How quickly must a data security incident be reported?

For personal data, Art. 33 GDPR applies with 72 hours from the date of knowledge to the supervisory authority. For facilities affected by NIS-2, Art. 23 NIS-2 also applies with 24-hour early warning, 72-hour follow-up report and final report to the BSI within one month. KRITIS operators must immediately report significant disruptions to the BSI in accordance with Section 8b BSIG. Deadline begins as soon as we become aware of it.

Do we need an ISB if we already have a DSB?

Yes, in most cases DPO and ISB are two separate roles with different mandates. The DSB is responsible for data protection in accordance with the GDPR, the ISB is responsible for the information security management system in accordance with ISO/IEC 27001:2022 or BSI-Grundschutz. NIS-2 affected facilities almost always require an ISB. Both roles can only be carried out by the same person if there are no conflicts of interest and sufficient capacity.

How much does a data security setup cost for a medium-sized company?

In practice, a classic structure with an internal ISB office, ISO 27001 certification and GRC tooling costs 180,000 to 420,000 euros per year, depending on the industry, sales and criticality of the data. With the CIVAC platform as a workspace plus an optionally ordered ISB, setup time and running costs can typically be reduced by 40 to 60 percent, without compromising the audit reliability of the documents.

Is a cloud certification from the provider enough for our data security?

No. Cloud providers such as AWS, Azure and Google are certified according to ISO/IEC 27001:2022, BSI C5 or SOC 2, but this only covers cloud infrastructure. In the shared responsibility model, configuration, identities, data, applications and processes remain with the customer. Anyone who relies solely on provider certification will fail in every audit. Your own ISMS remains required.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles